
Existing permissions are identified
Accounts and applications associated with the previous role are inventoried. Permissions required for the new responsibilities are identified, and unnecessary access is marked for removal. A role change is not limited to an update of the job title.
Verification and authorization are reviewed separately
The verification method is aligned with the sensitivity of the new access. Data and operation permissions are enforced separately. Successful second-factor verification is not accepted as unrestricted authorization within the application.
Changes are recorded
Permission removals and grants are recorded, and resulting access is checked against the approved role. During offboarding, related accounts, factors and sessions are handled through the departure process. Periodic reviews are scheduled to identify residual access.
An interdepartmental transfer example
When an account moves from finance to operations, existing permissions are compared with the new role’s needs. Direct grants, group memberships and temporary permissions are included in the review. Continued MFA enrollment does not validate previous permissions. Each retained entitlement is associated with an approving owner and a business reason so gradual privilege accumulation can be identified.
How is the review made traceable?
The previous and approved states are recorded separately. After implementation, necessary service access is tested and removal of unnecessary permissions is checked. Temporary assignments receive an end date and renewal owner. Applications outside centralized management are tracked independently to ensure that the approved change is implemented there as well.
Reference and scope
This planning guide is applied in accordance with organizational policy and documented system capabilities.
NIST SP 800-63B-4 — Authentication and Authenticator Management